๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ 58

Malware Analysis Series (MAS) – Article 9

Alexandre Borges์˜ ๋ธ”๋กœ๊ทธ Exploit Reversing์˜ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ 'Malware Analysis Series(MAS)'๋ฅผ ๋ฒˆ์—ญํ•˜์—ฌ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. MacOS/iOS ๋‚ด์šฉ์˜ ์•„ํ‹ฐํด 8์€ ์ž ์‹œ ๋ฏธ๋ค„๋‘๊ณ  9๋ฒˆ์งธ ์•„ํ‹ฐํด๋ถ€ํ„ฐ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. [Introduction]์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ(MAS)์˜ 9๋ฒˆ์งธ ์•„ํ‹ฐํด์— ์˜ค์‹  ๊ฒƒ์„ ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฒˆ ์•„ํ‹ฐํด์—์„œ๋Š” ์œˆ๋„์šฐ ์‹คํ–‰ ํŒŒ์ผ๋กœ ๋Œ์•„์™€์„œ PE ํฌ๋งท๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ์ผ๋ฐ˜์ ์ธ ์‰˜์ฝ”๋“œ(shellcode)๋ฅผ ๋‹ค๋ค„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์š”์ฆ˜์€ Sliver, Brute Ratel, Havoc, Covenant, Empire, Cobalt Strike ๊ฐ™์€ ์ˆ˜์‹ญ ๊ฐ€์ง€์˜ C2 ํ”„๋ ˆ์ž„์›Œํฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. Cobalt Strike๋Š” ์‹ค์ œ red team operation์—..

Malware Analysis Series (MAS) – Article 7

Alexandre Borges์˜ ๋ธ”๋กœ๊ทธ Exploit Reversing์˜ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ 'Malware Analysis Series(MAS)'๋ฅผ ๋ฒˆ์—ญํ•˜์—ฌ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. MAS ์‹œ๋ฆฌ์ฆˆ์˜ 7๋ฒˆ์งธ ์•„ํ‹ฐํด์ž…๋‹ˆ๋‹ค. [Introduction]์•…์„ฑ PE ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•  ๋•Œ ์‚ฌ์šฉํ•˜๋Š” ๊ฐœ๋…, ๊ธฐ๋ฒ• ๊ทธ๋ฆฌ๊ณ  ์‹ค์งˆ์ ์ธ ์ ˆ์ฐจ๋“ค์„ ์ด๋ฒˆ 7๋ฒˆ์งธ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ(MAS)์—์„œ ๊ณ„์†ํ•ด์„œ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ด๋ฒˆ์—๋Š” ์ตœ๊ทผ ๋ช‡ ๋…„๊ฐ„ ์—ฌ๋Ÿฌ ์ฐจ๋ก€ ์—…๋ฐ์ดํŠธ๋œ ๋ณต์žกํ•œ ๋ฑ…ํ‚น ํŠธ๋กœ์ด๋ชฉ๋งˆ์ธ Dridex๋ฅผ ๋ถ„์„ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ์•…์„ฑ์ฝ”๋“œ์™€ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ Dridex๋Š” ์ž๊ฒฉ์ฆ๋ช…(credental) ์ •๋ณด๋ฅผ ํƒˆ์ทจํ•˜๊ณ (kelogger ํ–‰์œ„), ์•”ํ˜ธํ™”๋œ C2 ์„œ๋ฒ„๋ฅผ ํ†ตํ•ด ๊ณต๊ฒฉ์ž์—๊ฒŒ ์ด๋ฅผ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. ๋Œ€๋ถ€๋ถ„์˜ ๊ฒฝ์šฐ ์•…์„ฑ ๋ฌธ์„œ์— ์ฒจ๋ถ€๋œ ํŒŒ์ผ๋กœ ๋ฐฐํฌ๋˜์ง€๋งŒ,..

Malware Analysis Series (MAS) – Article 6

Alexandre Borges์˜ ๋ธ”๋กœ๊ทธ Exploit Reversing์˜ ์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ ์‹œ๋ฆฌ์ฆˆ 'Malware Analysis Series(MAS)'๋ฅผ ๋ฒˆ์—ญํ•˜์—ฌ ๊ณต๋ถ€ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. MAS ์‹œ๋ฆฌ์ฆˆ์˜ 6๋ฒˆ์งธ ์•„ํ‹ฐํด์ž…๋‹ˆ๋‹ค. [Instruction]6๋ฒˆ์งธ ์•„ํ‹ฐํด์—์„œ๋Š” ๊ณ„์†ํ•ด์„œ ์•…์„ฑ PE ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ถ„์„ํ•  ๋•Œ ์‚ฌ์šฉ๋˜๋Š” ๊ฐœ๋…, ๊ธฐ๋ฒ•, ๊ทธ๋ฆฌ๊ณ  ์‹ค์งˆ์ ์ธ ์ ˆ์ฐจ๋“ค์„ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. ์ง€๊ธˆ๊ป ๊ทธ๋žฌ๋˜ ๊ฒƒ์ฒ˜๋Ÿผ ๋ถ„์„ํ•  ๋ชจ๋“  ์•…์„ฑ์ฝ”๋“œ ์ƒ˜ํ”Œ์€ Triage, Malware Bazaar, VirusTotal, Malshare, Polyswarm ๋“ฑ ์ž˜ ์•Œ๋ ค์ง„ ์ƒŒ๋“œ๋ฐ•์Šค ์„œ๋น„์Šค์—์„œ ๊ตฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธ€์—์„œ๋Š” ์•…์„ฑ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ์ ˆ์ฐจ๋“ค, ์ฆ‰ ๋ฐ”์ด๋„ˆ๋ฆฌ์— ๋Œ€ํ•œ ๊ธฐ๋ณธ ์ •๋ณด๋ฅผ ์–ป๋Š” ๊ฒƒ๋ถ€ํ„ฐ ๋ฐ”์ด๋„ˆ๋ฆฌ ์ž์ฒด์—์„œ ํ•ต์‹ฌ ์ •๋ณด๋ฅผ ์ถ”์ถœํ•˜๋Š” ๊ณผ..

[BumbleBee ๋ถ„์„ (3)] COM(Component Object Model) ๊ฐœ๋… ๋ฐ ๊ตฌ์กฐ์ฒด ์ ์šฉ

๊ณ„์† ์ด์–ด์„œ BumbleBee ์•…์„ฑ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.์ƒ˜ํ”Œ ํ•ด์‹œ(SHA256)๋Š” 57c4bdf0a644df4fd39f3d73d4570e6c88d8b7239ab4a395dba441ab15a5024f์ž…๋‹ˆ๋‹ค. ์ด๋ฒˆ ํฌ์ŠคํŒ…์—์„œ๋Š” ์ €๋ฒˆ์— ์ž ์‹œ ์‚ดํŽด๋ดค๋˜ ab_DetectVirtualMachines ์„œ๋ธŒ๋ฃจํ‹ด๋ถ€ํ„ฐ ์ž์„ธํžˆ ๋ถ„์„ํ•ด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. line 20์—์„œ ํ˜ธ์ถœํ•˜๋Š” ์„œ๋ธŒ๋ฃจํ‹ด sub_180050460์„ ๋”ฐ๋ผ๊ฐ€๋ณด๋ฉด COM๊ณผ ๊ด€๋ จ๋œ ์—ฌ๋Ÿฌ API๋“ค์ด ๋ณด์ž…๋‹ˆ๋‹ค.CoInitializeEx, CoInitializeSecurity, CoCreateInstance, CoUninitialize, CoSetProxyBlanket ๊ทธ์ค‘ CoCreateInstance API ํ˜ธ์ถœ ์‹œ์˜ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. CoCreateIns..

COM(Component Object Model)์˜ ๊ฐœ๋…

์˜ค๋Š˜์€ COM(Component Object Model) ๊ฐœ๋…์— ๋Œ€ํ•ด ์•Œ์•„๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค. โ—‹ COM(Component Object Model) ๊ฐœ๋…Microsoft์—์„œ ๊ฐœ๋ฐœํ•œ ์†Œํ”„ํŠธ์›จ์–ด ์ปดํฌ๋„ŒํŠธ ๊ธฐ๋ฐ˜์˜ ์ธํ„ฐํŽ˜์ด์Šค ํ‘œ์ค€์ž…๋‹ˆ๋‹ค.์ผ๋ฐ˜์ ์œผ๋กœ ํด๋ผ์ด์–ธํŠธ/์„œ๋ฒ„, RPC, ๋ถ„์‚ฐ ๊ฐ์ฒด์™€ ๊ฐ™์€ ๋ถ„์‚ฐ ์ปดํ“จํŒ… ๋ชจ๋ธ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์–ด๋–ค ์–ธ์–ด๋กœ๋“  COM ๊ฐ์ฒด๋ฅผ ์‰ฝ๊ฒŒ ์ž‘์„ฑํ•  ์ˆ˜ ์žˆ๊ณ , ๊ทธ ๊ธฐ๋Šฅ์„ ์ผ๋ฐ˜ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. โ—‹ COM ๊ตฌ์กฐ์˜ ํ•ต์‹ฌ ์š”์†ŒCOM ๊ฐ์ฒด์‹ค์ œ ๋™์ž‘ํ•˜๋Š” ์ธ์Šคํ„ด์Šค(instance)๋ฅผ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.์ตœ์†Œํ•œ IUnknown ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ๊ตฌํ˜„ํ•˜๊ณ  ์žˆ๋Š” ์ปดํฌ๋„ŒํŠธ ๋‹จ์œ„์˜ ๊ฐ์ฒด์ž…๋‹ˆ๋‹ค.IUnknown์€ ๋ชจ๋“  COM ์ธํ„ฐํŽ˜์ด์Šค์˜ ๊ธฐ๋ฐ˜์ด ๋˜๋Š” ์ธํ„ฐํŽ˜์ด์Šค์ด๋ฏ€๋กœ COM์˜ ๋ชจ๋“  ๊ฐ์ฒด๊ฐ€ ๋ฐ˜๋“œ์‹œ ๊ตฌํ˜„ํ•ด์•ผ๋˜๋Š”..

Study/study 2025.04.21